---
id: CVE-2025-66452
title: LibreChat is a ChatGPT clone with additional features
summary: >-
  LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and
  below, there is no handler for JSON parsing errors; SyntaxError from
  express.json() includes user input in the error message, which gets reflected
  in responses.…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: librechat
product: librechat
affected:
  - librechat <= 0.8.0
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66452'
references:
  - url: >-
      https://github.com/danny-avila/LibreChat/security/advisories/GHSA-q6c5-gvj5-c264
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00216
epssPercentile: 0.10972
ingestedAt: '2026-10-07T20:46:46.869Z'
---

## Overview

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have a fix at the time of publication.

## Affected

- `librechat <= 0.8.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
